AI agents do not just inherit too much access. They can also leave behind automation no one owns, so the organization keeps a machine-speed system running after the human creator is gone. That turns identity sprawl into a persistence problem, not just a privilege problem.
The sources tie that shift to developer-built agents that start with the creator’s permissions and to multi-agent workflows that can outlive the engineer who assembled them. The gap is inventory and ownership: teams may know the person left, but not what the agents still do or which access they still use.
The practical change is that standard offboarding and least-privilege checks no longer cover the full exposure. If teams are letting AI helpers read mail, code, or internal systems and take actions, they also need to account for the automation that survives the account holder.